Skip to content

Latest commit

 

History

History
232 lines (172 loc) · 11.2 KB

File metadata and controls

232 lines (172 loc) · 11.2 KB
title Quantum resistance
title-aliases
Post-quantum cryptography
topic-categories
Security Enhancements
optech_mentions
title url feature
Discussion of quantum computer attacks on taproot
/en/newsletters/2021/03/24/#discussion-of-quantum-computer-attacks-on-taproot
true
title url
Question about paying public keys directly versus hash indirection
/en/newsletters/2020/04/29/#what-are-the-potential-attacks-against-ecdsa-that-would-be-possible-if-we-used-raw-public-keys-as-addresses
title url
Question about whether taproot create security risk from quantum threats?
/en/newsletters/2020/02/26/#could-taproot-create-larger-security-risks-or-hinder-future-protocol-adjustments-re-quantum-threats
title url
Question about whether hashing pubkeys really provides quantum resistance?
/en/newsletters/2019/10/30/#why-does-hashing-public-keys-not-actually-provide-any-quantum-resistance
title url
Bitcoin Core contributor meeting transcripts: taproot quantum discussion
/en/newsletters/2019/06/12/#taproot-accumulator-quantum
title url
BIP151 discussion, including about NewHope quantum-resistant key exchange
/en/newsletters/2018/09/11/#bip151-discussion
title url
PR opened for initial BIP151 support, NewHope quantum resistance to follow
/en/newsletters/2018/08/28/#pr-opened-for-initial-bip151-support
title url
Discussion about quantum-safe key exchange
/en/newsletters/2022/04/20/#quantum-safe-key-exchange
title url
2022 year-in-review: quantum-safe key exchange
/en/newsletters/2022/12/21/#quantum-safe-keys
title url
Consensus-enforcement of quantum-resistant lamport signatures without consensus changes
/en/newsletters/2024/05/08/#consensus-enforced-lamport-signatures-on-top-of-ecdsa-signatures
title url
Draft BIP for quantum-safe address format
/en/newsletters/2024/06/14/#draft-bip-for-quantum-safe-address-format
title url
Discussion about an upgrade path using taproot in case fast quantum computers are created
/en/newsletters/2025/01/03/#quantum-computer-upgrade-path
title url
Update on BIP360 pay-to-quantum-resistant-hash (P2QRH)
/en/newsletters/2025/03/07/#update-on-bip360-pay-to-quantum-resistant-hash-p2qrh
title url
Discussion about whether quantum-vulnerable bitcoins should be destroyed to prevent theft
/en/newsletters/2025/04/04/#should-vulnerable-bitcoins-be-destroyed
title url
Discussion of Guy Fawkes signatures to protect some current bitcoins against quantum theft
/en/newsletters/2025/04/04/#securely-proving-utxo-ownership-by-revealing-a-sha256-preimage
title url
Draft BIP for destroying quantum-insecure bitcoins
/en/newsletters/2025/04/04/#draft-bip-for-destroying-quantum-insecure-bitcoins
title url
Report about quantum computing and Bitcoin
/en/newsletters/2025/06/06/#quantum-computing-report
title url
Prototype implementation of Winternitz signatures for Bitcoin using `OP_CAT`
/en/newsletters/2025/07/04/#op-cat-enables-winternitz-signatures
title url
Commit/reveal function for post-quantum recovery of insecure bitcoins
/en/newsletters/2025/07/04/#commit-reveal-function-for-post-quantum-recovery
title url
Research indicates many Bitcoin primitives are compatible with quantum-resistant signatures
/en/newsletters/2025/07/25/#research-indicates-common-bitcoin-primitives-are-compatible-with-quantum-resistant-signature-algorithms
title url
Discussion about forcing migration from quantum-vulnerable outputs
/en/newsletters/2025/08/01/#migration-from-quantum-vulnerable-outputs
title url
Paper analyzes the security of taproot commitments against quantum computers
/en/newsletters/2025/08/01/#security-against-quantum-computers-with-taproot-as-a-commitment-scheme
title url
SLH-DSA (SPHINCS) post-quantum signature optimizations
/en/newsletters/2025/12/05/#slh-dsa-sphincs-post-quantum-signature-optimizations
title url
Technical report of hash-based post-quantum signature schemes
/en/newsletters/2026/01/02/#hash-based-signatures-for-bitcoin-s-post-quantum-future
title url
Brassard-Høyer-Tapp (BHT) algorithm and Bitcoin
/en/newsletters/2026/01/30/#brassard-hoyer-tapp-bht-algorithm-and-bitcoin-bip360
title url
SHRINCS: 324-byte stateful post-quantum signatures with static backups
/en/newsletters/2026/02/06/#shrincs-324-byte-stateful-post-quantum-signatures-with-static-backups
title url
Falcon post-quantum signature scheme proposal
/en/newsletters/2026/02/06/#falcon-post-quantum-signature-scheme-proposal
title url
SLH-DSA verification can compete with ECC
/en/newsletters/2026/02/06/#slh-dsa-verification-can-compete-with-ecc
title url
Hourglass V2 proposal to limit P2PK spends
/en/newsletters/2026/03/06/#hourglass-v2-update
title url
Discussion of cryptographic algorithm agility in Bitcoin
/en/newsletters/2026/03/06/#algorithm-agility-for-bitcoin
title url
Discussion of the limits of cryptographic algorithm agility in Bitcoin
/en/newsletters/2026/03/06/#the-limitations-of-cryptographic-agility-in-bitcoin
title url
Compact Isogeny PQC can replace HD wallets, key-tweaking, silent payments
/en/newsletters/2026/04/03/#compact-isogeny-pqc-can-replace-hd-wallets-key-tweaking-silent-payments
title url
SHRIMPS: 2.5 KB post-quantum signatures across multiple stateful devices
/en/newsletters/2026/04/03/#shrimps-2-5-kb-post-quantum-signatures-across-multiple-stateful-devices
title url
BIPs #1895 publishes BIP361, a post-quantum migration and legacy signature deprecation proposal
/en/newsletters/2026/04/24/#bips-1895
title url
Post-quantum HD wallets with fallback SPHINCS keys
/en/newsletters/2026/05/01/#post-quantum-hd-wallets-with-fallback-sphincs-keys
title url
Discussion of a post-quantum output type
/en/newsletters/2026/05/01/#discussion-of-a-post-quantum-output-type
title url
Proposal to embed post-quantum keys in tapscript without consensus changes
/en/newsletters/2026/05/01/#proposal-to-embed-post-quantum-keys-in-tapscript-without-consensus-changes
title url
Post-quantum BIP86 recovery using zk-STARK proofs of BIP32 seeds
/en/newsletters/2026/05/01/#post-quantum-bip86-recovery-using-zk-stark-proofs-of-bip32-seeds
title url
A post-quantum path for BIP324
/en/newsletters/2026/06/05/#a-post-quantum-path-for-bip324
title url
Post-quantum Lightning discussion
/en/newsletters/2026/06/05/#post-quantum-lightning-discussion
title url
Quantum attack game theory
/en/newsletters/2026/06/05/#quantum-attack-game-theory
title url
BIPs #2198 makes one-path P2MR outputs unsafe to discourage omitting a post-quantum fallback leaf
/en/newsletters/2026/06/26/#bips-2198
title url
Benchmarking SLH-DSA STARK aggregation
/en/newsletters/2026/07/03/#benchmarking-slh-dsa-stark-aggregation
title url
Bird of Prey 2 (BoP-2) non-malleable schnorr and PQ signatures
/en/newsletters/2026/07/03/#bird-of-prey-2-bop-2-non-malleable-schnorr-and-pq-signatures
title url
Lattice-based signatures
/en/newsletters/2026/07/03/#lattice-based-signatures
title url
Triggering EC disabling with a NUMS point spend or hashrate majority
/en/newsletters/2026/07/03/#triggering-ec-disabling-with-a-nums-point-spend-or-hashrate-majority
see_also
title link
Taproot
topic taproot
title link
Version 2 P2P transport
topic v2 p2p transport
excerpt **Quantum resistance** is the ability for cryptographic protocols to remain secure in the presence of fast quantum computers.

Bitcoin uses a variety of cryptographic protocols with varying degrees of vulnerability to fast quantum computers:

  • SHA256, SHA256d, and RIPEMD160 used variously in Bitcoin's proof of work and to uniquely identify blocks, scripts, individual transactions, and collections of transactions, plus used for hash locks in [HTLCs][topic htlc], would have their security strength reduced to its square root by [Grover's algorithm][] running on an idealized quantum computer. That means an algorithm like SHA256 that currently has an estimated second preimage resistance of 256 bits (2256) would be reduced to 128 bits (2128 is the square root of 2256). That loss can be overcome by using a roughly equivalent algorithm with twice as many security bits, e.g. going from SHA256 to SHA512.

  • ECDSA public keys used in Bitcoin are vulnerable to a factorization attack using [Shor's algorithm][]. This would completely eliminate the security of ECDSA, assuming an idealized quantum computer. Since public keys used for proposed [schnorr signatures][topic schnorr signatures] are essentially identical to those used for ECDSA, the same attack applies. Quantum-resistant alternatives to ECDSA are known, but they involve much larger key and signature sizes, so most developers seem to prefer to delay upgrading until it's necessary.

  • Noise is the [protocol framework][noise framework] used for encrypted communication in LN. Optech has not seen discussion of its quantum resistance, but we believe the way LN currently uses it depends on the security of ECDSA, so if fast quantum computers are developed, they may be able to decrypt old communication between LN nodes.

The worst case for attacks assumes an idealized quantum computer with sufficient capacity and reliability to perform the attack. It's likely that the capacity and reliability of quantum computers will increase gradually over time, meaning the security of the cryptography used in Bitcoin will similarly decrease gradually over time, with attacks progressing from computationally infeasible, to theoretically possible but implausible, to extraordinarily expensive, to very expensive, to practical. As long as this progression is followed and is possible to publicly track, it's likely Bitcoin can continue using its currently highly space efficient cryptography while it remains safe, and then upgrade to post-quantum cryptography when it looks like it'll soon become necessary.

{% include references.md %} {% include linkers/issues.md issues="" %} [grover's algorithm]: https://en.wikipedia.org/wiki/Grover%27s_algorithm [shor's algorithm]: https://en.wikipedia.org/wiki/Shor%27s_algorithm [newhope]: https://newhopecrypto.org/ [noise framework]: https://duo.com/labs/tech-notes/noise-protocol-framework-intro